Reverse Engineering CTF Challenges
Static/dynamic analysis & binary deobfuscation.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
Reverse engineering is the practice of taking a compiled artefact and recovering what it does. In a CTF context the artefact is usually a stripped Linux ELF binary or a Windows executable that hides a flag behind some logic: a comparison you have to satisfy, an encryption routine you have to break, or control flow that has been deliberately twisted so a decompiler renders it as gibberish.
The skill being tested is patience plus structure. Nobody reverses a 4 MB binary by reading it top to bottom. You probe it first — run it, see what it does, feed it inputs and watch what changes — then narrow to the function that matters and only then start reading carefully. Good reversers form a hypothesis, test it cheaply, and discard it just as fast.
You do not need to be an expert to score here. A working knowledge of x86-64 calling conventions, the C runtime library and common compiler idioms covers most of what a mid-difficulty challenge asks for.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Flag checks
The classic form: a routine compares your input against a transformed value. You recover the transformation, invert it, and recover the flag.
Obfuscated control flow
Opaque predicates, flattened dispatch tables and switch tables inserted specifically to defeat decompilers, requiring manual reconstruction of the real logic.
Packed and encrypted payloads
Binaries whose meaningful code is unpacked at runtime, so static analysis shows a stub. You need to dump the process after the unpacking stage completes.
Anti-analysis
Timing checks, debugger detection and environment probes that must be identified and bypassed before the real logic will run.
Embedded data
Flags or keys embedded as byte arrays, decoded by a small routine buried somewhere in a large binary. The reverse part is locating the decoder.
Algorithm reimplementation
Custom hash, compression or cipher routines you must reimplement in another language to compute a comparison value or decrypt a blob.
Tools you’ll reach for
- Ghidra
- IDA Free
- radare2 / rizin
- GDB & pwndbg
- strace / ltrace
- x64dbg (Windows)
- Frida
- Python + capstone / pyelftools
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Complete a Ghidra course — the "Intro to Reverse Engineering" free course from the training.github.com Ghidra track is the right starting point.
Learn enough x86-64 to read a decompiled function without flinching: calling convention, stack frame, and what `rbp`-relative reads mean.
Always run the binary first. Even when it does nothing useful, `strings`, its dynamic dependencies and its runtime behaviour tell you what to decompile.
Practise on crackmes.one from easy to medium. There is no substitute for the first twenty binaries.
Learn the handful of Ghidra shortcuts that matter — rename, retype, force-integer — because manual naming is what makes a function readable.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
Reverse Engineering is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.